Building Inclusive and Secure Open Source Communities with Emily Fox – Techstrong Unplugged EP35
Emily Fox, TOC Chair of the CNCF, discusses the vital work happening across the cloud-native ecosystem. Emily shares insights into the CNCF’s Technical Oversight Committee, their focus on environmental sustainability, and the role of working groups in fostering innovation and inclusivity. She also dives into the importance of partnerships, security in open source projects, and how creating friction-free security practices benefits developers and users alike.
Transcript
Welcome back to Text On Unplugged. My name is Cassandra Chin, and today we're here with Emily Fox, who's the TOC Chair of the CNC App. Hi.
Thank you so much for having me, Cassandra. It's a pleasure to be here today. So I know like you're a part of a whole lot of things at the CNCF.
I would like to learn more about the things you're a part of. Okay. Um, so I am the chair of the Technical Oversight Committee.
It's a group of 11 technologists who responsibility is to assist and support our projects within the ecosystem to make sure they're healthy, um, to provide guidance around how do we engineer our projects to be robust and resilient so that we can encourage adopters to integrate them within their infrastructure and architectures. Um, as part of my role on the TOCI am also the liaison to the technical advisory group on environmental sustainability and the technical advisory group for contributor strategy. But I I, I'm often showing up in a lot of different places beyond just those official roles.
Do you wanna talk more about the environmental sustainability, the ability working group? Yeah. Um, so the, that TAG is one of our newer ones.
It's, um, been around for at least a year. It's, it's been a while. The all the time starts to run together.
Um, they're focused on increasing awareness and efficiency of cloud native projects. Um, there is, within the European Union, a heavy and increased focus and regulation on environmental sustainability and carbon footprint of, uh, computing technologies. And in the US we don't quite have the same things.
So, uh, what we're trying to do with projects through that group is allow them to better understand what their CPU utilization is, what their software, carbon intensity footprint actually is, and see if there are different configurations or options for deployment that reduces the carbon intensity of cloud native projects for the benefit of all adopters. But what a lot of people don't realize is if you're designing your systems and programming them to be efficient in the use of your cloud resources, not only are you helping the environment, but you're also potentially getting cost savings back and doing that. And that's really where the US market is finding a lot of value in those technologies, whether or not they realize it yet, There's a lot of working groups.
But how do you join or, Um, well, first off is showing up to any of the technical advisory group meetings, finding a topic of interest to you. Um, we have, like you said, a lot of different working groups within our CNCF tags. Um, within environmental sustainability, there's the Green reviews working group who's working specifically on that software, carbon intensity measurement for cloud native projects within tag contributor strategy, we have our, uh, deaf and hard of hearing working group, who has been fabulous to see them show up to CubeCon.
Um, we have our, you'll Be interviewing them. We, Yes, yes. Catherine Hagan has been great.
She's a, she's a force to be reckoned with within that group. Um, there's also the Bipoc working group, black and indigenous people of color. Um, they're, we, they tried starting a blind and visually impaired working group.
We're trying to identify more individuals in the community to join that one. Um, within TAG security, there's software supply chain, but really all it is, is have an interest in an area, or even if you're not sure what specifically you wanna focus on, show up to a TAG meeting first, ask some questions, um, ask about the working groups and what it is that they're focused on, and then start showing up to meetings and asking more questions and seeing where you can help out or during the conversation. That Almost reminds me of a school club.
It that's kind of like what they are. So if you're, if you're familiar with the culture of like school clubs and after school kind of activities, that's a lot of what these are. It's groups of like-minded people or people coming to learn in, in a healthy and inclusive and inviting space to either advance their careers or advance their knowledge or even share what it is that they have and mentor and guide others along the way.
It sounds really great that we have all this programs. Yes. Yes, it is.
The CNCF is one of the more unique clinics, foundation projects in that we are very community centric. It's one of the things that I hear the most about when I talk to individuals in the community is how welcome and how accepted they feel. And more than just, uh, ticking a compliance checkbox, if you will, it's actually genuinely interested in having you come, having you participate, helping with the PR review, leading or facilitating a meeting, engaging in conversation and connecting with others.
Is this like probably my fifth cube con and I've definitely seen that over the past couple years. Yeah. Like Really, I feel welcome here.
That, that's great to hear. We, um, as a former co-chair for the event, we've often struggled to find ways in which we can allow new attendees to the conference that are overwhelmed. How do they find their path?
And, and navigating both the conference for the first time, but also the community after that and following up with those individuals that they meet in the hallway track, for instance. Um, that's why we started things like Contrib Fest, which is a place for cloud native projects to hold special sessions and invite potential contributors in to learn about the project and get hands on and fixing some of the bugs or features or even collaborating on a new, uh, enhancement proposal to a project, for instance. It's a ga it's a wonderful way of kind of getting your feet wet in the ecosystem in a comfortable place where everybody is learning.
Do You wanna talk more about the cloud native ecosystem and how all these projects work? Hi, I can certainly do that. Um, so we have over 200 projects within CNCF.
I think the last number was 209, um, was what I saw. We have three different levels. Um, within CNCF sandbox projects are new, early, innovative experimental projects.
Um, they come into the ecosystem. It's a low barrier to entry. We just ask a few questions, make sure you're cloud native.
Um, from there, sandbox projects can grow to maturity and then they can apply to become incubating projects, which is when they're a little bit more robust in their engineering practices. They have, um, semantic versioning in their releases or some form of versioning in their releases. They have a good contributor guide.
They have good open governance that informs new contributors how to come into the community and get started. Um, they also, uh, allow, um, that's the first time that we start our adopter interviews as well, is understanding how is the open source project being consumed by entities, uh, financial services organizations, um, cloud service providers, things of that nature, and allows us to kind of assess, um, what's going on. And then providing that feedback to the project.
From there, um, they go to graduation level, which is fully robust, highly mature projects that are very resilient. Um, they're a widespread adoption at multiple companies and organizations around the world. And this is kind of the, the next, this is like the, the peak of cloud native for a project to be able to achieve.
But not everybody gets there. Sometimes we do archive projects. They've tried something, it didn't quite work out.
They didn't quite get adoption or the maintainers moved on to something else. And we always celebrate those because we tried something, we learned. And that documentation is now available for the rest of the community to, to learn from and move forward.
I think a lot of people and companies use these open source projects, so it's really great that the CNCF is there to like really support the project and give it some stability. Yep. We, but it, the CNCF doesn't just do it by itself.
Um, uh, as you said, there's a lot of organizations that adopt and consume our open source projects, and there's a few of 'em that do give back either through engineering resources, maybe five to 10% of their work time to contribute and, uh, do feature fixes and changes back into projects. But there's always never enough. Um, so we're always looking for organizations that are interested in this space, but might have a little bit of trouble of understanding and navigating open source.
How do I get started? How do I contribute to a project? What, what's a technical advisory group and how do I get involved?
Why would I get involved with those? Um, we're always seeking them out and we've created new programs, like, uh, zero to Emerge is run by CNCF, which is a, uh, cohort program that runs periodically to allow engineers in the ecosystem to actually understand what it is to contribute to an open source project and how to do it. So we have a lot of great programs that invite people in.
I think we need to bring more awareness to these programs. We do. The number one complaint I get from attendees at the conference is, I don't know where to start.
And there's just so many things. io. It's a fabulous website.
We have information on there for contributors to projects as well as maintainers of projects. Um, we even have an amazing accessibility page on there. So if you are, um, even if you're not in C ncf f if you're interested in inviting more underrepresented groups, um, and promoting accessibility within your project or even your event, um, check out the accessibility portion of the website.
There's a lot of wonderful resources there. I Really love how much the CMCF supports accessibility and diversity. Yeah, there's, for myself, we're currently in like an open source recession where we see companies pulling back on either their investment in open source or their contributions to open source.
And we don't do enough, in my opinion, of opening access to open source projects to underrepresented or even marginalized groups. And it's very difficult because a lot of the technical leadership of these projects come from big businesses, large organizations, and they have the opportunity to either give a talk at a conference such as CubeCon or lead an event or run a meeting within the community. And it, if you're from a marginalized group, it's difficult to see yourself in a similar position unless there's someone else already there.
So what we try to do is create this space where people can find their people, their community, in a way that is welcoming and allows them to just, uh, explore and discover different paths into leadership or into how do I jointly deliver a conference talk with somebody from the deaf and hard of hearing working group? How do I make that networking connection if you don't have those resources internal to your company? 'cause Cloud Native is an international and global community.
We wanna make sure that you not only are working with your, uh, colleagues and your business on an open source project, but that you're also being exposed to different perspectives and use cases that you will only get through open source. It's all very important. It is.
And like earlier you mentioned that the CNCF has a connection to other communities. Yes. We do have a lot of community members who either are, um, participants in other open source foundations, uh, for, uh, tag security and CNCF.
Several of the members there and even co-chairs participate in the open source security foundation. So you'll see a lot of security, uh, professionals at CNCF events and a lot of cloud native professionals at some of the security events that open SSF runs. Um, there's also individuals that work between communities.
Um, one of our open source projects, uh, confidential containers is in collaboration with the confidential computing consortium who's looking to advance confidential computing technologies and make them accessible for adopters. So we see great innovation happening there. There's been more discussions with LF AI and data with our, um, tag runtime AI working group.
So they've had some good discussions there. There is also, um, the Chaos Group. I just, I just had a conversation with Don Foster from tag contributor strategy about chaos and what all they're doing and some awesome projects they have, like Aspen and Eight Knot, which allow people to understand more about the health and the practices of open source projects.
Um, I'm sure there's like a ton of them that I am forgetting, but there's at least one person in CNCF who's been here for a long time is involved in at least one other foundation or group. Like what are some of the benefits that you get from like meeting with other foundations in group, Um, alignment on bigger industry projects? One of the things that I've recently gotten involved in through Open SSF side is the security baselines effort, which is an effort by community members to work through and define what is the floor of security for open source and what does that look like?
How do we make that, um, a good base for all open source foundations to potentially leverage. Um, and we wanna do it in a way that it's not just human generated content. We want it to be automated and detectable and do it in a way that it's not yet another checklist, but make it simple for projects to understand how to achieve those security outcomes if we're successful.
That allows us to instrument changes within like the open SSFs best practices badging structure. So it's not just about good engineering practices anymore. It's about good engineering practices that promote security outcomes and that helps adapters of open source in meeting regulations such as the upcoming CRA that is going to go into effect within the next couple of years Whenever I heal hear security, like I think of security conferences where you just have a group of security minded people, but I feel that actually everyone needs to learn about this, which is why like partnerships is really important.
Yes, ed, I'm of the belief that we can't sense offer engineers back to school to become security professionals. It's just, it's not a good use of anyone's time. But what we as security professionals can do is make security more accessible and easier to consume and adopt for technologists that are working in cloud native or other environments on virtualization technologies.
So the easier we can make it for them, the more likely they are to actually adopt security best practices and ensure that they're not deploying a container with a vulnerable image into their production environment. Because we've made the pipelines for deployment so robust and incentivize the software engineers to want to do the right thing. I don't think that anybody purposefully wants to defeat any security policy, but when the security policy is constantly telling, you know, you can't deploy, but not telling you why they get frustrated.
So my, one of the things that I'm passionate about is making security more accessible and friction free. And I think by following all the security principles, we're like protecting ourself, lead users, other developers. I think everyone gets a benefit from It.
Yep. We talk about defense in depth within the security community a lot, but we talk about it in the context of our operational infrastructure and architectures. What we don't think about is if we start security in our open source projects as the start of our software supply chains, we can actually build defense in depth over time through those hands off.
If it's a dependency in pi PI for instance, and there's a project that consumes that into their open source image and it goes through a secure build pipeline that has in Toto Atest station and SBO M and SLSA provenance that comes out of it, all of that starts to accumulate and build this wonderful body of evidence for adopters of open source to continue to build on ultimately until it ends up with an end user who can make an informed decision. That's true defense in depth. And it goes well beyond just your operational infrastructure environment.
It's a lot to take in. It is a lot, But really I've learned a lot from you today. Thank you so much.
Thank you, Emily. It was pleasure being here. Thank you so much for having me.
